Cognitive-Maps Based Investigation of Digital Security Incidents
Rekhis, S.; Krichene, J.; Boudriga, N.
Systematic Approaches to Digital Forensic Engineering, 2008. SADFE apos;08. Third International Workshop on
Volume , Issue , 22-22 May 2008 Page(s):25 - 40
Digital Object Identifier 10.1109/SADFE.2008.20
Summary:Investigation of security incidents is of great importance as it allows to trace back the actions taken by the intruders. In this paper we develop a formal technique for digital investigation based on the use of Incident Response Probabilistic Cognitive Maps. Three main issues are addressed here: (1) construction and extraction of plausible known attack scenarios, (2) construction of hypothetical scenarios and their validation using a logic-based formalism, and (3) selection of optimal counter-measures addressing the detected attacks.
View citation and abstract |